IBM Rational Developer for System z SSL Certificate Local Information Disclosure Vulnerability
BID:56725
Info
IBM Rational Developer for System z SSL Certificate Local Information Disclosure Vulnerability
| Bugtraq ID: | 56725 |
| Class: | Design Error |
| CVE: |
CVE-2012-4862 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 26 2012 12:00AM |
| Updated: | Nov 26 2012 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Rational Developer for System z 8.5.1 IBM Rational Developer for System z 8.5 1 IBM Rational Developer for System z 8.0.3 3 IBM Rational Developer for System z 8.0.3 2 IBM Rational Developer for System z 8.0.3 1 IBM Rational Developer for System z 8.0.3 IBM Rational Developer for System z 8.0.2 IBM Rational Developer for System z 8.0.1 IBM Rational Developer for System z 7.6.2 4 IBM Rational Developer for System z 7.6.2 3 IBM Rational Developer for System z 7.6.2 2 IBM Rational Developer for System z 7.6.2 IBM Rational Developer for System z 7.6.1 IBM Rational Developer for System z 7.5.1 4 IBM Rational Developer for System z 7.5.1 3 IBM Rational Developer for System z 7.5.1 IBM Rational Developer for System z 8.5 IBM Rational Developer for System z 7.6 IBM Rational Developer for System z 7.5.0 IBM Rational Developer for System z 7.1 |
| Not Vulnerable: | |
Discussion
IBM Rational Developer for System z SSL Certificate Local Information Disclosure Vulnerability
IBM Rational Developer for System z is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
IBM Rational Developer for System z versions 7.1, 7.5, 7.5.1, 7.5.1.3, 7.5.1.4, 7.6, 7.6.1, 7.6.2, 7.6.2.2, 7.6.2.3, 7.6.2.4, 8.0.1, 8.0.2, 8.0.3, 8.0.3.1, 8.0.3.2, 8.0.3.3, 8.5, 8.5.0.1, and 8.5.1 are affected.
IBM Rational Developer for System z is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
IBM Rational Developer for System z versions 7.1, 7.5, 7.5.1, 7.5.1.3, 7.5.1.4, 7.6, 7.6.1, 7.6.2, 7.6.2.2, 7.6.2.3, 7.6.2.4, 8.0.1, 8.0.2, 8.0.3, 8.0.3.1, 8.0.3.2, 8.0.3.3, 8.5, 8.5.0.1, and 8.5.1 are affected.
Exploit / POC
IBM Rational Developer for System z SSL Certificate Local Information Disclosure Vulnerability
An attacker can exploit this issue using standard commands.
An attacker can exploit this issue using standard commands.
Solution / Fix
IBM Rational Developer for System z SSL Certificate Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM Rational Developer for System z SSL Certificate Local Information Disclosure Vulnerability
References:
References: